DID-Linked Verifiable Credentials for Domain Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing domain name registration systems rely on central registries for managing and verifying user identifiers, which can be unreliable and inefficient, lacking in trust and security.

Innovation Solution

Associating decentralized identifiers (DIDs) with verifiable credentials (VCs) to enable domain names to claim associations with other identifiers, allowing secure and trusted transmission of user information without relying on central registries, and enabling bi-directional verification of identities and ownership.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central repository of data is used to verify domain name content, then verification can be performed, but the system becomes unreliable and inefficient due to dependency on central registries

Engineering Contradiction:
Improveverification reliabilityVSAvoidcentral registry dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized verification system into decentralized components by distributing verification credentials to domain name servers. Each DNS can independently verify credentials without relying on a central registry, breaking the monolithic centralized system into autonomous segments that maintain verification capability while eliminating single-point failure dependencies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the verification credential data from the central registry and embeds it directly into the domain name server infrastructure. By taking out the essential verification information and placing it at the edge (DNS level), the system eliminates the need for continuous central registry involvement while maintaining verification reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If central registries are used to manage domain name verification, then verification processes can be executed, but computational resource usage increases and efficiency decreases

Engineering Contradiction:
Improveverification efficiencyVSAvoidcomputational resource usage
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent implements self-service verification by enabling domain name servers to autonomously verify credentials using locally stored verification data. The system serves itself by distributing verification capabilities to individual DNS, eliminating the need for continuous centralized processing and reducing overall computational resource consumption while maintaining verification efficiency.

Inventive Principle:
Principle #25Self-service

3Reliability

If decentralized identifiers are associated with verifiable credentials, then security and trust are enhanced, but the system complexity increases

Engineering Contradiction:
Improvetrust and securityVSAvoiddecentralized framework complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-associating verifiable credentials with domain names during the domain registration process. This advance preparation stores verification data in advance at the DNS level, so that when verification is needed, the process is simple and direct without requiring complex real-time centralized coordination, thus enhancing security while managing complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12512993B2Verifier credential determination by a registrant
Publication Date: 2025.12.30 VERISIGN INC
  • US12512993B2 patent drawing
  • US12512993B2 patent drawing
  • US12512993B2 patent drawing

AI summary

Techniques for associating verifiable credentials with a decentralized identifier are described herein. A computing device can determine a link between a decentralized identifier (DID) and a domain name, and assign a verifiable credential to the DID to invoke an action associated with the domain name. For example, the verifiable credential can be used to control an identifier on a platform different than the domain name. In some examples, a registrar can validate an identity of the registrant based on the decentralized identifier. The computing device can use the verifiable credential identified in the decentralized identifier to provide secure verifications of an identity.